Verify that you successfully added the data source
Confirm that the data source you added is successfully parsing events.
- In Splunk UBA, select Manage > Data Sources.
- Click the name of the data source that you added.
- Review the Data Source Details.
- Click the parsed events icon () and review the 10 sample events. Make sure that each event lists event views.
Some data sources, such as DHCP, DNS, AD, or HTTP do not provide a destination device. If you ingest one of these data types and see validation error messages, you can ignore these messages once you examine the raw event and validate the absence of the destination device in the raw event.
Run the script after adding data source
You can run the following script after adding a data source to verify that the system is up and running. Additional exceptions noted by the script indicate custom configuration steps or other issues that need remediation.
/opt/caspida/bin/utils/uba_health_check.sh
Non-CIM complaint mapping for cloud storage data | Monitor the quality of data sent from the Splunk platform |
This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.2.0, 5.2.1, 5.3.0, 5.4.0, 5.4.1
Feedback submitted, thanks!